PT-2021-15555 · Keybase · Keybase Desktop Client

Aubrey Cottle

+3

·

Published

2021-02-22

·

Updated

2021-09-08

·

CVE-2021-23827

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Keybase Desktop Client versions prior to 5.6.0 on Windows and macOS Keybase Desktop Client versions prior to 5.6.1 on Linux
Description: The issue allows an attacker to obtain potentially sensitive media, such as private pictures, in the Cache and uploadtemps directories. This occurs because the client fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.
Recommendations: For versions prior to 5.6.0 on Windows and macOS, update to version 5.6.0 or later. For versions prior to 5.6.1 on Linux, update to version 5.6.1 or later. As a temporary workaround, consider restricting access to the Cache and uploadtemps directories until a patch is applied.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23827

Affected Products

Keybase Desktop Client